Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

NetSupport RAT

41
Global rank
58 infographic chevron month
Month rank
48 infographic chevron week
Week rank

NetSupport RAT is a malicious adaptation of the legitimate NetSupport Manager, a remote access tool used for IT support, which cybercriminals exploit to gain unauthorized control over systems. It has gained significant traction due to its sophisticated evasion techniques, widespread distribution campaigns, and the challenge it poses to security professionals who must distinguish between legitimate and malicious uses of the underlying software.

RAT
Type
Unknown
Origin
1 September, 2017
First seen
17 September, 2026
Last seen

How to analyze NetSupport RAT with ANY.RUN

RAT
Type
Unknown
Origin
1 September, 2017
First seen
17 September, 2026
Last seen

IOCs

IP addresses
2.23.246.9
151.240.151.68
23.48.23.173
74.179.77.164
2.16.204.151
48.209.138.189
23.59.18.102
2.21.239.138
48.209.138.168
20.165.94.63
172.66.2.5
48.192.1.65
172.211.123.250
204.79.197.203
176.65.144.73
162.159.142.9
20.190.190.196
95.100.102.101
23.216.77.21
88.221.169.152
Hashes
63aa18c32af7144156e7ee2d5ba0fa4f5872a7deb56894f6f96505cbc9afe6f8
8793353461826fbd48f25ea8b835be204b758ce7510db2af631b28850355bd18
32d83ff113fef532a9f97e0d2831f8656628ab1c99e9060f0332b1532839afd9
4bfa4c00414660ba44bddde5216a7f28aeccaa9e2d42df4bbff66db57c60522b
6ffe12cdfe0a36dec4b4a40ecdafb4097b1af7c340b0fcecf9f5c67b7fa8b299
2dfdc169dfc27462adc98dde39306de8d0526dcf4577a1a486c2eef447300689
7852fce59c67ddf1d6b8b997eaa1adfac004a9f3a91c37295de9223674011fba
53b4be3ed1cfd712e53542b30cfe30c5db35cc48be7c57727dfec26c9e882e90
be9aeaeab5a2e4899ba7e582274ba592c1b9baf688b340a754b8ef32b23cfa9c
96ad1146eb96877eab5942ae0736b82d8b5e2039a80d3d6932665c1a4c87dcf7
4dbfc417d053ba6867308671f1c61f4dcafc61f058d4044db532da6d3bde3615
56ebaf8922749b9a9a7fa2575f691c53a6170662a8f747faeed11291d475c422
25973a78051dcbfe80b2cbf4db85b2dd14a913d294b48b2dfbdf3619fe8c3140
c36b5c170d1e59a957fc67f17df28605e275ec6e01f3d4c03531f6fd251c5189
2edf10f0af08c32b7721becc063297d09362e76e1f5a18f0d81837752363b578
e6b595c19b931960c18d562fe16bd4fa05d724b812d10945c2f965bf836783a8
aa4fc4eb78d08de797220a8b9c1db3f8a584ffcb85dda47b71a11eb306280395
1d13ea5b0ba74bd3105c84713cacf38477ce8efea982408692e55aa561e28217
e079857637cf263244005c274d4e5e54f65f19e347b96e420f56b3ead1de68d2
d96856cd944a9f1587907cacef974c0248b7f4210f1689c1e6bcac5fed289368
Domains
ocsp.digicert.com
fe3cr.delivery.mp.microsoft.com
th.bing.com
www.microsoft.com
bikaloffff.com
dns.msftncsi.com
go.microsoft.com
settings-win.data.microsoft.com
crl.microsoft.com
activation-v2.sls.microsoft.com
client.wns.windows.com
lindegogcflin.com
otaiakkkkd.com
self.events.data.microsoft.com
slscr.update.microsoft.com
ecs.office.com
login.live.com
nexusrules.officeapps.live.com
oneocsp.microsoft.com
www.bing.com
URLs
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/microsoft%20secure%20server%20ca%202026.crl
https://settings-win.data.microsoft.com/settings/v3.0/wsd/updatehealthtools?os=windows&osver=10.0.19041.1.amd64fre.vb_release.191206-&sku=48&deviceclass=windows.desktop&locale=en-us&deviceid=s:bad99146-31d3-4ec6-a1a4-be76f32ba5d4&sampleid=s:95271487&appver=10.0.19041.3626&flightring=retail&telemetrylevel=1&hidovergattreg=c%3a%5cwindows%5csystem32%5cdriverstore%5cfilerepository%5chidbthle.inf_amd64_9610b4821fdf82a5%5cmicrosoft.bluetooth.profiles.hidovergatt.dll&appver=&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&oemmodel=dell&updateoffereddays=4294967295&processormanufacturer=authenticamd&installdate=1661339444&oemmodelbaseboard=&branchreadinesslevel=cb&oemsubmodel=j5cr&isclouddomainjoined=0&deferfeatureupdateperiodindays=30&isdeviceretaildemo=0&flightingbranchname=&osuilocale=en-us&devicefamily=windows.desktop&wuclientver=10.0.19041.3996&uninstallactive=1&isflightingenabled=0&osskuid=48&processorclockspeed=3094&totalphysicalram=6144&securebootcapable=0&app=sedimentpack&processorcores=6&currentbranch=vb_release&installlanguage=en-us&deferqualityupdateperiodindays=0&oemname_uncleaned=dell&tpmversion=0&primarydisktotalcapacity=262144&installationtype=client&attrdataver=186&processormodel=amd%20ryzen%205%203500%206-core%20processor&isedgewithchromiuminstalled=1&osversion=10.0.19045.4046&ismdmenrolled=0&activationchannel=retail&firmwareversion=a.40&trendinstalledkey=1&osarchitecture=amd64&defaultuserregion=244&updatemanagementgroup=2
https://www.bing.com/dsb/scenario?name=trendingsearchwithcache&cc=us&setlang=en-us
https://www.bing.com/dsb/search?dsbmr=1&format=dsbjson&client=windowsminiserp&dsbschemaversion=1.1&dsbminiserp=1&q=q&cc=us&setlang=en-us&clientdatetime=9%2f17%2f2026%2c%204%3a45%3a23%20pm
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbtrjrydryt%2bapf3gspypfhbxr5xtqqus9tippmhxdiunkhmewnpyim8s8yceajtxtab8my1oj8mfwpz%2f7y%3d
http://oneocsp.microsoft.com/ocsp/mfqwujbqme4wtdajbgurdgmcgguabbq3l3%2f%2fa6adk8nray2gxzvayrhg4aqub6t%2b2v%2bxq3lso2d33ojhnyhhqoucezmaaaafuwohyjguzpcaaaaaaau%3d
https://www.bing.com/threshold/xls.aspx?t=5&dl=1&f=9&wsbc=1
https://www.bing.com/th?id=odswg.199e6001-5b8b-4c66-963c-b7a12927c8e3&pid=dsb
https://www.bing.com/as/api/windowscortanapane/v2/suggestions?qry=p&setlang=en-us&cc=us&nohs=1&qfm=1&seahisoff=1&cp=1&cvid=52cf7ecbad7840148596262b0c96bbfb&ig=3db35e9948284c4abc098ef3c64b3a94
https://www.bing.com/as/api/windowscortanapane/v2/suggestions?qry=po&setlang=en-us&cc=us&nohs=1&qfm=1&seahisoff=1&cp=2&cvid=52cf7ecbad7840148596262b0c96bbfb&ig=9df1c73c5bef44d8ad9f9374ca79e465
https://th.bing.com/th?id=odswg.iotdlocalicon&w=16&h=16&c=1&rs=1&p=0
https://www.bing.com/as/api/windowscortanapane/v2/suggestions?qry=pow&setlang=en-us&cc=us&nohs=1&qfm=1&seahisoff=1&cp=3&cvid=52cf7ecbad7840148596262b0c96bbfb&ig=c7b43e5125584ea7b0e27e74aac2293c
https://www.bing.com/as/api/windowscortanapane/v2/suggestions?qry=powe&setlang=en-us&cc=us&nohs=1&qfm=1&seahisoff=1&cp=4&cvid=52cf7ecbad7840148596262b0c96bbfb&ig=66559b4f8aa441e8b65bc4f127791f0e
https://www.bing.com/as/api/windowscortanapane/v2/suggestions?qry=power&setlang=en-us&cc=us&nohs=1&qfm=1&seahisoff=1&cp=5&cvid=52cf7ecbad7840148596262b0c96bbfb&ig=2fcb5e03c3b8467f9772ff2c2c49c5e2
https://go.microsoft.com/fwlink/?linkid=2257403&clcid=0x409
http://lindegogcflin.com/
http://www.microsoft.com/pkiops/crl/microsoft%20ecc%20update%20secure%20server%20ca%202.1.crl
https://slscr.update.microsoft.com/sls/%7b522d76a4-93e1-47f8-b8ce-07c937ad1a1e%7d/x64/10.0.19045.4046/0?ch=686&l=en-us&p=&pt=0x30&wua=10.0.19041.3996&mk=dell&md=dell
http://www.microsoft.com/pkiops/crl/microsoft%20ecc%20update%20signing%20ca%202.3.crl
Last Seen at

Recent blog posts

post image
How MSSPs Can Prove Their Value When “Nothing...
watchers 1351
comments 0
post image
Enterprise Threat Intelligence Buying Guide:...
watchers 1647
comments 0
post image
ANY.RUN & SentinelOne: One Workspace, Ins...
watchers 3241
comments 0

What is NetSupport RAT Malware?

NetSupport Manager, developed in 1989, is a legitimate remote administration tool designed for technical support. It enables file transfers, support chat, inventory management, and remote access. It is widely used in corporate environments for employee training and workstation management.

Cybercriminals repurposed it as a Remote Access Trojan RAT, known as NetSupport RAT.

In its malware variant, NetSupport RAT is deployed without consent, often via deceptive methods like fake browser updates, phishing emails, or compromised websites. It uses obfuscated scripts (e.g., JavaScript, PowerShell) to install the NetSupport client (e.g., client32.exe) covertly, establishing persistence through registry keys and connecting to malicious command-and-control (C2) servers. Unlike the legitimate tool, it operates in stealth mode to evade detection.

Since at least 2017, NetSupport RAT has been abused in campaigns, notably surging in 2020 during a COVID-19-themed phishing campaign and continuing into 2025 with sophisticated delivery methods like encrypted .doc files and fake CAPTCHA lures.

Attackers commonly deliver NetSupport RAT through:

  • Phishing emails with malicious links or attachments (e.g., PDFs, LNK files)

  • Malvertising campaigns that redirect to fake update/download pages

  • Compromised websites serving drive-by downloads

  • Trojanized software installers

  • Social engineering ("tech support" scams)

    The malware often employs obfuscation techniques and names its processes to resemble legitimate Windows services.

The Trend of Abusing Legitimate Remote Access Tools

The abuse of legitimate remote access tools is a significant shift in cybercriminal tactics observed since the late 2010s. It has intensified with the rise of remote work, providing attackers with more opportunities to deploy trojanized versions through phishing, drive-by downloads, or compromised websites.

Legitimate tools are less likely to be flagged by antivirus software, as they have valid digital signatures and established reputations. Besides, the network traffic generated by these tools appears normal, making detection through network monitoring more difficult.

This trend extends beyond NetSupport to include other popular remote access solutions like TeamViewer and AnyDesk.

NetSupport RAT Victimology

NetSupport RAT campaigns typically target sectors with valuable data or critical operations:

  • Educational institutions;
  • Healthcare providers;
  • Government agencies;
  • Small and medium businesses (SMBs);
  • Individual users via phishing;

Many attacks begin with phishing emails or malicious ads leading to drive-by downloads, often posing as software updates or urgent security tools. Geographically, attacks are widespread, with notable activity in North America, Europe, and Asia. Both large organizations and small-to-medium enterprises are targeted, as the RAT’s versatility allows attackers to exploit vulnerabilities across diverse environments.

NetSupport RAT Typical Attack Chain

There is a variety of NetSupport RAT samples in ANY.RUN’s Interactive Sandbox detonated and analyzed by over 15,000 SOC teams. Let’s see the malware in action on an example.

View analysis

NetSupport RAT analysis in sandbox NetSupport RAT sample analysis in the Interactive Sandbox

The run begins on the hacked ahaci.com page that shows a fake Cloudflare check. It tells the victim to press Win + R and paste a “verification code”. That text is really a PowerShell one liner. It hides the console with -w h, bypasses the policy with -ep Bypass, creates a GUID file in %TEMP%, downloads yLp.dof from 185.177.239.214 (about 9 MB), and starts a second hidden PowerShell with -f pointing to that script. In the first tracer (PID 4116) you can clearly see Guid::NewGuid(), the curl call, and the follow up execution that hands control to the loader which will fetch and deploy NetSupport RAT.

PowerShell operations deploying NetSupport RAT PowerShell process deploying NetSupport RAT

The second PowerShell process (PID 7384) is the loader for NetSupport RAT components. It calls System.Convert::FromBase64String many times, each time getting back data that starts with MZ, so real PE files. It writes them straight to %APPDATA%\kHLiHMC\ using System.IO.File::WriteAllBytes.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

The names match known NetSupport parts: pcicapi.dll, PCICHEK.DLL, PCICL32.DLL, TCCTL32.DLL, and remcmdstub.exe. Between every write the script sleeps for 108 to 400 milliseconds which looks like an attempt to slow the pattern of API calls.

PowerShell process deploying NetSupport RAT PowerShell process loading NetSupport RAT components

Persistence is created through the registry for the NetSupport client. The script sets HKCU\Software\Microsoft\Windows\CurrentVersion\Run\rMBhIvmVX to C:\Users\admin\AppData\Roaming\kHLiHMC\client32.exe. With this Run key in place, NetSupport RAT will start every time the user logs on.

Registry edit establishing NetSupport RAT persistence Registry edit establishing NetSupport RAT persistence

After the binaries are in place, client32.exe runs (PID 788). It reaches geo.netsupportsoftware.com/location/loca.asp for a quick geo lookup and then sends several small POST requests to 83.222.190.174/fakeurl.htm. From here NetSupport RAT waits for commands from that C2, polling for tasks while staying quiet on the endpoint.

NetSupport RAT network activity on endpoint NetSupport RAT network activity on endpoint

How Does NetSupport RAT Function?

NetSupport RAT operates through a client-server architecture that mirrors its legitimate counterpart. The malicious client component installs on victim systems and establishes communication with attacker-controlled servers. The malware leverages standard networking protocols, often HTTP/HTTPS, to blend with legitimate traffic.

The technical architecture includes several key components: a lightweight client agent that installs on victim systems, command and control servers that receive victim connections and relay attacker commands, and administrative interfaces that provide attackers with user-friendly control panels for managing compromised systems.

Communication protocols employ various obfuscation techniques to evade network-based detection. These may include custom encryption schemes, protocol tunneling, and domain generation algorithms for command and control server locations. The malware also implements sophisticated persistence mechanisms, including Windows service installations, registry modifications, and integration with legitimate system processes.

The modular design allows attackers to deploy additional capabilities as needed, including specialized data harvesting modules, cryptocurrency mining components, and proxy tools for further network exploitation.

What NetSupport RAT Can Do to User Device

Once installed, NetSupport RAT grants attackers extensive control over compromised endpoints. Its capabilities include:

  • Remote Desktop Control: Full access to the victim’s screen for real-time monitoring and manipulation.
  • Data Exfiltration: Ability to capture screenshots, audio, video, and sensitive files.
  • File Management: Uploading and downloading files to introduce additional malware or steal data.
  • System Manipulation: Modifying settings, launching applications, and establishing persistence via registry changes.
  • Surveillance: Keylogging and webcam access to monitor user activity. These features enable attackers to conduct reconnaissance, steal credentials, or move laterally within a network.

How NetSupport RAT Malware Threatens Businesses and Organizations

For businesses and organizations, NetSupport RAT represents a multifaceted threat that extends far beyond individual endpoint compromise. The malware's capabilities enable several high-impact attack scenarios that can severely damage organizational operations and reputation.

  1. Data Breaches and Intellectual Property Theft: Attackers can systematically identify and exfiltrate valuable intellectual property, customer databases, financial records, and strategic planning documents.
  2. Financial Fraud and Business Email Compromise: Attackers can observe legitimate financial transactions, intercept banking credentials, and manipulate payment processes to redirect funds to attacker-controlled accounts.
  3. Ransomware Deployment: The comprehensive system access allows attackers to disable security tools, map network resources, and deploy ransomware across entire organizational networks.
  4. Compliance and Regulatory Impact: Data breaches facilitated by NetSupport RAT can trigger significant regulatory penalties under frameworks like GDPR, HIPAA, and SOX.
  5. Operational Disruption: Even without deploying additional malware, NetSupport RAT can significantly impact business operations through system performance degradation, unauthorized system modifications, and network congestion from data exfiltration activities.

Gathering Threat Intelligence on NetSupport RAT Malware

Threat intelligence plays a critical role in:

  • Identifying new NetSupport RAT campaigns and tactics
  • Sharing Indicators of Compromise (IOCs) across organizations
  • Enabling faster detection and response
  • Providing context on attacker motivations and infrastructures

Start gathering IOCs and behavioral data with the malware name search request to Threat Intelligence Lookup:

threatName:"netsupport"

NetSupport RAT malware samples found via TI Lookup NetSupport RAT malware samples found via TI Lookup

You can also search TI Lookup for samples abusing other Remote Monitoring and Management tools using the rmm-tool tag:

threatName:"rmm-tool"

Malware samples abusing remote access tools found via TI Lookup Malware samples abusing remote access tools

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

NetSupport RAT exemplifies how trusted tools can be subverted for malicious purposes. Its stealth, versatility, and abuse of legitimate software make it a persistent threat to both individuals and organizations.

The trend toward abusing legitimate remote access tools reflects an evolution in cybercriminal tactics and calls for security approaches that go beyond traditional signature-based detection. Organizations must implement comprehensive defense strategies that combine technical controls, user education, and threat intelligence to effectively combat this threat.

Gather fresh actionable threat intelligence via ANY.RUN’s TI Lookup: start with 50 trial requests.

HAVE A LOOK AT

Zloader screenshot
Zloader
zloader trojan loader
Zloader is a banking trojan that uses webinjects and VNC clients to still banking credentials. This Trojan is based on leaked code from 2011, but despite its age, Zloader’s popularity has been only increasing through early 2020, when it relied on COVID-19 themed attacks.
Read More
DarkTortilla screenshot
DarkTortilla
darktortilla
DarkTortilla is a crypter used by attackers to spread harmful software. It can modify system files to stay hidden and active. DarkTortilla is a multi-stage crypter that relies on several components to operate. It is often distributed through phishing sites that look like real services.
Read More
Bert Ransomware screenshot
Bert Ransomware is a newly emerged ransomware group that has been active since April 2025. It deploys variants targeting both Windows and Linux systems, focusing on critical sectors like healthcare, technology, and event services across the US, Asia, and Europe.
Read More
DarkVision screenshot
DarkVision
darkvision
DarkVision RAT is a low-cost, modular Remote Access Trojan that gives attackers remote control of infected Windows hosts. Initially observed around 2020 and sold in underground marketplaces, DarkVision has become notable for its full feature set (keylogging, screen capture, file theft, remote command execution and plugin support) and for being distributed via multi-stage loaders in recent campaigns.
Read More
GravityRAT screenshot
GravityRAT
gravity
GravityRAT is a sophisticated spyware and remote access trojan that has been actively targeting organizations and government entities since 2016. It uses innovative anti-analysis techniques and made an evolution from a Windows-only threat to a cross-platform espionage tool capable of compromising Windows, Android, and macOS systems.
Read More
SSLoad screenshot
SSLoad
ssload
SSLoad is a malicious loader or downloader that is used to infiltrate target systems through phishing emails, perform reconnaissance and transmit it back to its operators delivering malicious payloads. To avoid detection, SSLoad employs various encryption methods and delivery techniques highlighting its versatile nature and complexity. It is believed to be a part of Malware-as-a-Service (MaaS) operation given its diverse delivery methods and implemented techniques.
Read More